#general
1 messages Β· Page 1614 of 1
I use keyboard
Wsl?
it still doesnt work
work device, i dont think they will allow me to use wsl
Lmao
Then you will have to use the copy paste tool, it will have an arrow on the left side of the AttackBox screen
CPTS
Ctrl + Shift + T on my linux
Crazy
windows key + enter on my linux
Do u know for windows
thanks
Gave +1 Rep to @mossy river (current: #6 - 1750)
All Iβve heard about cpts is that it teaches more than u need for oscp
windows + x gives you a menu where you can click terminal
but i think win r might be the fastest
Windows key on Linux 
since it remembers what u put in
its on my keyboard?
why not use it
I'd rather not πππ₯
its only on windows
I'll do ctrl + T if it's customizable
really you should try
Bro 5 fingers ππ
you'll spend a lot of time on that when you grow older
ctrl t is also to open a new tab in the web
All thing that I can say.
Learn the red path in THM.
Complete.
Then you can't find any new points to add in your notes.
Maybe 5 to 10 %
so u might run into issues
Oh
id do ctrl shift t then
I'll find something else
What is win + T for!
?
Win + T doesn't exist
I'll use that
But now i need to learn how to customise commands
The Win + T keyboard shortcut cycles focus between apps on your Windows taskbar, allowing you to select and open a taskbar item by pressing the Enter key.
is what gemini says
For example in pivoting you don't learn here too many tools at the same time.
But you can find them on the Internet and use them and learn on your own.
Like chisel and ligolo-ng
id incorporate a shift or some other modifier
Alrr
Best value for money is THM. Platform.
ligolo goated for what Iβve heard
Does it teach you or help you with critical thinking ? Whatβs your opinion on that
Can you solve easily boxes for oscp, for example or boxes in thm or htb
Real
I believe you can manage to pass the OSCP and beyond. Just with THM and maybe 2 months for THM normal subscription.
I wish u the best man fr
U can check out reddit r/oscp
Lots of people document their paths on tackling it
There are the list of those boxes that are like OSCP in the Internet and YouTube.
You can find them.
win + M and win + J do nothing
After you are comfortable with the red path in THM and THM networks you can try 2 months HTB subscription and then go for pass any exam PT1 or OSCP or others
The "Win + M" shortcut minimizes all open windows on your desktop, while the alternative "Win + D" shortcut also shows the desktop but can be pressed again to restore the previous windows. he Windows key + J shortcut in modern Windows operating systems (Windows 10 and 11) functions as an accessibility shortcut to set focus on a Windows tip, such as a Windows Spotlight tip or a notificatio
says gemini
what r u trying to do?
he wants to open his terminal in the fastest way possible
But pt1 is introductory like ejpt and oscp is highly regarded as really difficult
u want 4 windows?
my path is PT1 β> cjca β> cbbh β> cpts β>oscp
OSCP is difficult because of the ban of Automatic stuff
whats autohotkey
Free keyboard macro program. Supports hotkeys for keyboard, mouse, and joystick. Can expand abbreviations as you type them (AutoText).
ohhh
Windows kids when they realise that every single icon on their desktop is actually just a script that starts the game because they're too lazy to learn CLI
Free keyboard macro program. Supports hotkeys for keyboard, mouse, and joystick. Can expand abbreviations as you type them (AutoText).
no way
yeah thats the link
https://open.spotify.com/artist/4EM8OVxT4yk8jkqPqGnEG8
This shi goes hard
Did you guys know that you don't need to type the name of the song if you have the link
In spotify app
u can just copy the link in searchbar
and it finds it
what if you click the link
chances of it being a phishing link with just homoglyph attack 
This is okay but spending too much money on certification that doesn't land you in a job is not a good thing.
CLI is mad fun
At one point it just clicks and you don't even think about what to type
?
what u on about
guess who jus learned how to open spotify through CLI
haha
but how tf do i remember all those directories
now make it into a batch script and put it on your desktop
boom you made a shortcut
the hard way
?
why did u question mark
just make shortcuts, put all your shortcuts in one directory
wdym
why would you need to
the location of for example spotify.exe
to run apps?
the directory is just the place where the file is located at
yes
you can go check it manually if u want
ehm
i need to go to the directory first to run
you can just type "spotify"
the crucial ones you will remember with experience
@stable pier what if you do spotify without the .exe
you dont need the full path if u mean that
doesnt that jus increase my time
doesnt work
?
it does for me
how
yeah it should
OPH YAA ITS WORKING
? I will go directly for OSCP.
After that it is not necessary doing too many certifications
im confused
am I the only one who doesn't understand why cmd exists? Powershell exists
cmd came before powershell
yes but things evolve
if stuff is in your path env variable u can just type the name
There are many other things that are existing in windows from the beginning of the windows until now.
So
in case of spotify it is because of "%USERPROFILE%\AppData\Local\Microsoft\WindowsApps" I believe
then turn it off

like if i wanna run this ill havr to remember that i have to change directory to D:\nini9te?
run by default > turn it off 
tbh I mostly use cmd
same
why, powershell is great and cross platform
Yaa me too
also cmd is limited
dont need the features often
everything has limits
powershell > cmd
running linux on my powershell
imagine typing cmd when u cna do ctrl + alt + J
cmd does the tasks that needs to be done
still 3 keystrokes
im so sleepy
web fundamentals too, is done
imagine using windows as a main os
comfortable ones
i do
congrats bro
i do aswell
think again bro
im so sleepy
did you ever install arch?
and convienent
yea i still have it on VM
Congratulations πππ
BRO ITS FINE GENUINELY
not baremetal though
when i buy a seperate SSD, ill install baremetal on it
Cool
Windows as main OS.
This is the only stable option for gaming.
arch for someone who uses windows as main os is a mistake
but do you game?
but linux isnt perfect too
also windows has improved
windows for gaming
Yeah. Sometimes
ive used alot of distros of linux
linux not for gaming
i use kali for almost the whole day
time to download hyprland manually
when studying cybersec
I don't have that luxury of gaming time
why not?
Got some bluetooth connectivity issues but it's fine i guess 
i game for sometime
when my friends call me up
and sometimes i play batman and witcher games when im bored
try Athena os, it's a child between kali and arch
When my Brain doesn't works. I will do something else like playing games or Keyboard πΉ
i have checked it out before
it never caught up with me
and arch does?
arch is funn
i installed arch simply for the experience
and knowledge
i use it once in a while
not as my main
Parrot os.
do u like arch
It took some tries but u got it to work 
experience in what? setting an Wi-Fi card, d
format drives and creating users?
yea the rice worked
fortunately
its good to know
Yyyaaaaa

just ricing and stuff
trying out hyprland
I knew how to do that before the whole arch hype
cool
good for you!
also where is this arch hype?
can i not increase my partitions volume once its shjrinked
So the vm was the problem?
yea i think so
it worked in vbox
Nice π
have fun kratos
6 years ago when I started learn Linux everyone were using debian, nowdays everyone suggest arch
Don't really think it goes like that
I have a good memory of fighting with that last Valkyries in God of war.
times change
You need to have foundational certs
stability is the most important pillar for a system
Best experience of your life
at least here
Yes
is that really the case or is this just some internet people
and it makes sense
debian is love
arch is just an abusive partner
π
arch just breaks if you don't use for a month
Damn arch vs debian is going on
@tight trout Might kill me for this statement
can't take breaks
Linux Mint.
Number one in distro watch
and then you gotta fix it
that's a lie
from which you can learn
because she can't cope with the reality 
why you lying to arch
Number 2 : CachyOS
which is ubuntu, which is debian 
mint is the best for beginners tbh
which is gnu
yeah mint is great
Hello Guys, who here uses ServiceNow for Self, I mean not for a company
Yeah but Debian is not beginner friendly.
Lmao THIS
debian cli is awesome
Every time I installed Debian WIFI problem
arch is the best
CachyOS also makes it easy if u are bored
I use debian on risc-V and I love it
debian is best
I use Arch
Yes true
btw
Now cachy
this is kinda like the apple vs android discussion
Ubuntu is literally based off deb
I use vista vm in arch
they both suck nowdays π¦
i personally have never used an iphone so i cant speak for those, my android device is pretty good
yum
the era of custom roms on android is dying
Every OS is a tool.
"Always use the right tool for the right job."
One sentence from Farcry6
did you try #site-support
Apple sucks, not because of the phone or the components but because of the company's policies and systems in place
there people can help
That are purely made to squish the last bits of money from developers
i tried everything
what's the latest iPhone that actually have something new than camera modules? iPhone 14?
they invented apple glass
none
or something
lmfao
well, imo the problem is that there aren't enough support staff
apple ass
liquid glass
The apple chips are nice
i dont even know
u got a mic?
What county you are in?
This for just a room?
idk man my time on the cert is being wasted, this is so shit
I can help you out
Anyone Please
the cert i think
does it make any difference lmao
they just are the worst bc no FOSS support
wtf??
?????
If your country banned VPN you can't connect
If there is a genuine bug, you will receive your time back.
Liquid ass
You're doing a cert exam without knowing how to connect to vpn?
Which cert is it @analog prawn
Are we just donating money to THM
hell no dude, it isnt fucking banned
π
Alright watch the language
hes capping
its been HOURS since i made a ticket and my VPN wont connect at all, like genuinely i downloaded and reconfigured 8 times already
well, support staff get hundreds of emails
lmao are you crazy?
and not may people
What's your site username?
may I dm please?
vc?
It's different support
oh, I see
You can't help with Certs.
Just hop in vc and screenshare, it's prob something small
oh oopsie, ignore what i said then
no dude ive done tons of certs, this is my first time im getting a problem ffs
Nope, it is an exam, helping with certs is against the terms.
I can see why for like actual stuff but troubleshooting an issue?
alright then lol
because you can't decide whether it's user issue or a genuine bug
I'll focus on my own studies haha
and if you help them with part of the exam, their exam is invalid
guess who just learned taskkill /im spotify.exe
cool
Ah alr
also what happened with the ticket event
i also learned
winget install
yeah winget is amaizng
@mossy river who can I talk about ctf prizes?
winget bitcoin\
If it's blue team or intrusion, me
let me dm you then
if its red team , me
Can you not comment? @mossy river
it's ofc alr if not
but
would be nice to hear
Wym?
it was going on yesterday
there was a ticket event?
its still going on I believe
Had everything in dashboard page and I even earned a few
but can't see it anymore
and can't earn tickets no more
I don't
no they rolled it back I believe; think because of bugs
oh, I see
I literally finished a room....
for it.....
and it wasn't even open?!
π
π
Ye jabba we need a bit of more transparency with this π
Is it cancelled, being fixed, or should it be going right now?
dont think its canceled
that would be weird
doesnt it start on september 1st?
It was on yesterday
lol
maybe they accidentally leaked it yesterday
this is what the newsletter says
guys do you know about the webinar of the tryhackme today
it would start from semptember 1st
bet ya they leaked it then
also makes more sense to start on a new month
yup
then a random day in august
so it was an accident
idk about any webinar
i dont wanna say yes or no
probably imo
but π€·
only the staff or jabba can comment
I wonder if it was because of me reporting the bug on the page that they realised it's alrd going on by accident lol
or the mods
you don't know about any webinar of tryhackme
that would be funny
I don't know of any webinar that is happening today
26th of june
what about this one
that was 2 months ago
thats in june
Damn
easy time travel then
lol
What Every SOC Should Know: Top 5 Gaps Exposed in 30+ Real-World TTX Scenarios Confirmation
about this one sorry that was a wrong one
you sure thats THM's?
its tryhackme
where did you see that then
cuz if there was a webinar
usually
it is in announcements
the event hasn't started yet
yeah, then it was probably a bug yesterday
is there any webinar of the tryhackme
ngl, doesn't sound like a thm webinar title
this is one part image of the webinar registration page and the following is the link
https://tryhackme.zoom.us/webinar/register/7017556830785/WN_P8auUdjyTBC2LjecmvPhuw#/registration
it is today
Usually every Wednesday
I got a mail invitation too
oh so there is a event?
that one hasnt been announced yet then?
since this is the only message with that in it
I haven't gotten an email about it
I'm on phone sorry for the resolution
π€·
so the webinar is happening today i was right
that's what it says in the email
so have you registered

is anyone here into malware analysis and would like to help dismantle a criminal setup on disc
That would be illegal, we can't help you here
pentester here looking to learn soc cause no pentesting jobs in my country π
π i feel the pain
thats why i did CDSA when everyone was doing CPTS
wdym btw i only asked about the registration for that
is the webinar will happen today
If that's what it says on the registration site then yes
ok thanks for being saying to me like this
Gave +1 Rep to @mossy river (current: #6 - 1751)
really? did you try unsolicited applications?
wait a sec
(I'm not in the field)
or freelancing? or is that rare because of legal concerns?
Which country
yeah, that doesn't work

if you reply to me with a thanks it will work

of course
take a guess
Berlin, Germany
if only you knew how hard it is to explain Nist2 to some companies here
"Rust Programmers with anime pfp talking about type safety while they don't their job safety"
thank god I don't dox myself
Gave +1 Rep to @tidal sierra (current: #108 - 81)
Reverse Engineering malware isn't illegal :)
Otherwise countless security researchers would be jailed for it, and teams like Red Canary wouldn't exist
They're trying to dismantle a discord c2
Yes, that's standard ops for security research
Nothing wrong with the malware analysis it's the interacting with Discord that's the problem
Detraced successful killed the supply chain to a malware too
Does that make our work illegal?
Are you an unlicensed Discord counter phishing team?
If they file the report to discord to terminate the server, it's above board
It's completely legal to dismantle a C2 as long as it's done in accordance to laws
heloo
Which is why we could take down supplychains swiftly
I'm not going to bother arguing with you
Dismantling a C2 isn't just "heck it" and you're down lol
π
hi! how to learn rev engineering in depth considering that I am a complete beginner?
I read your blog, its really amazing
for dir in $(echo $PATH | tr ':' ' '); do [ -w "$dir" ] && echo " Writable directory found: $dir"; done
heyyy
isnt reverse engineering malware reserved for the advanced channels?
I have salary negotiations today
in terms of possibly keeping my job after my education is done
I wasn't saying how to do so
no no i know
I was just explaining the process isn't actually illegal
Regardless, this isn't a Discord vigilante server
i was just too lazy to get the docs command
Otherwise many upon many groups would be arrested
i think the best course of action would still be to contact law enforcement
It would be
It would also decentivise a lot of things
That's what you're doing as part of the investigation
You need evidence it's being used as a C2 though
It's not for 14 year olds on Discord to be doing though is it
Which is available in general through the Malware
Since when did age matter for research and defence?
By interacting with the service you can disrupt ongoing investigations - and by deploying the malware yourself you can be violating unauthorised access laws, just because people don't get prosecuted doesn't mean it's not a crime
Shouldn't you be encouraging people and not gatekeeping
No I'm not going to encourage people to take down illegal crime rings, if you want to do that, go into some sort of law enfrocement position
How do you think crime rings get taken down lol
There's gotta be someone who's found it and filed evidence
there are a lot of fun and positive things to learn in cyber better than learning malware dev.
Often times it's taken down by.. a law enforcement agency.
Those that are taking it into their own hands and taking down servers are literally breaking the law
They asked about rev eng
Not maldev
How do they find out those details to take it down? A lot of the time it's through public sources and a kid with a keyboard
genuinely amazed at how good people are when it comes to arguing
so does no one can ask question here about malware analysis or reverse engineering
more like discussing than arguing
You can submit a report without needing to interact with the service, stop trying to justify the other person's intentions when they very clearly weren't going to report it to law enfrocement
i asked, but people are too busy pointing shit at each other
it all depends on context
why?
depends on context, but malware dev is said in advanced channels
You need evidence during a report otherwise it's dismissed
the channels for the cool kids
lol
is there anything happening in those channels or are they dead
pretty dead
but btw what the jabbe and the ashyboop are saying what are they talking about
yeah thought so
but every now and then people talk there
Evidence in the case of malware is IOCs or other identifiers, even defanged samples
π€·
could you tell us about what topic is going on so that we can jump right in
Cause according to Jabba every researcher should be jailed by his logic
Kids in cyber krime WTF
probably best to leave it to Jabba and Ashlynn
Nope, you're just twisting my words for your own benenfit π
guys I have a question, what do you tell non-tech people when they ask what you do ?
I'm not lmao
uhhh, explain generally what your job is
You called asking for help with rev eng and analysis illegal
i try to explain how the soc works in simple terms, so a little device between your internet connection that listens etc
That's a you screw up
You ARE NOT a security researcher if you spend your time asking for help dismantling cyber crime groups on Discord
Iβm straightforward
That is not what they were asking for was it
As if us security researchers never get stuck π€£
so what both of you are saying how every researcher could be jailed everyone in the hacking world is a researcher so all of them could be jailed for being doing research
I've had to throw out cries before to externals cause I got roadblocked by whatever Anti-Analysis Feature
true
Alright this discussion is no longer productive
Guess I'm not a security researcher
I don't believe so, but as Jabba said, the discussion is no longer productive, so
Just a script kiddy or someone with intend of fraud or scam do this kind of things.
so who is the winner of this discussion you are the ashy
nah but i would just read the whole discussion, that will make it more clear
in telegram is the same situation
no one
it is a discussion
No such thing as a winner of a discussion
not an argument with a winner or loser
i think thats where u are right
so ok it was just for fun
no it was about a burger king coupon
winner will be announced next week
id love one of those
which winners will be announced next weak
he's joking
I absolutely suck at changing gears and leaving clutch slowly
the winners of the burger king coupon
oh you guys got me this time
its muscle memory, comes with time. i also still struggle with it sometimes
and in every car its different
You don't actually need to contact authorities to dismantle a C2, if it's above board
Many, many, many, service providers actually give you an abuse line to contact where you can report the C2 being ran on that service. Completely legal and above board
I f you have a C2 hold it for yourself π there is no need to publish it on discord and saying. I have this server and I scan this countries
are you new to driving? still in driving school?
Honestly you just get used to it after a certain point, buy a cheap car you don't mind runining the clutch in
It's how we brought down the supplychain for the ransomware we're dissecting
In this case, a physical C2 would need authorities
What exactly do you struggle with when changing gears? @topaz sedge
But most C2s aren't physically hosted, they're under a VPS or other hosting scheme
Theyβre like you can hear when you need to change gears. Hear what? I canβt hear anything π€£
Typically only large scale C2s handled by APTs are physical
yeah
lets pls change gears wrt discussion
hi stealth why they are showing new with you
your car will be loud
then its time to shift
They all sound loud to the autist π
real
See while this is true, a lot of people will go to 3k/4k revs to make it loud π
What if it's rattling 
I know the car I drive so well that I don't actually listen or check the revs most of the time, it is purely muscle memory
Hi talo
Most of the time, I shift off the speedometer and the sound
have you left server once and came back again i think that you have done something like this
It's about every 25-35km/h
When I went for driving lessons she changed her car π₯Ή I had to start again
However, when I first started driving I listened for the car and then remembered around where the revs should be to gear change, the car also does have a screen to tell you when to shift but I find that going just under the revs it tells you to shift is perfect for a clean gear change
"e, the car also does have a screen to tell you when to shift" my shitbox doesnt π
I did a 20-hour two week course and I drove the car perfectly until the day before the lesson and I stalled 8 times on the same round-a-bout π
Slowly conditioning the server to forget I exist. π if I keep doing it one day they wonβt notice.
Ψ
it also depends on what u wanna do, if u wanna conserve gas u shift gears faster than if u wanna speed
It's only a fiat panda π€£ It's my girlfriend's car, she doesn't have a license so I drive it
sorry didn't get it
my previous car did have it but its not too acurate in my experience
Every car has its own gearbox specifications and intricacies
Ye
True.. I burn a lot of fuel, I push the revs so I can go faster π¬
i want a new one
I need help in the JVM Reverse Engineering
Can anyone help me out?
DM Pls
My instructor would say, how are you driving normally today and last week you couldnβt drive. Then the next week I couldnβt drive again π
I feel like it's good enough for learners to rely on, but I never listen to it
thanks bud
my car has an eco function so when Iβm bored I turn this on and it keeps the revs low automatically and I change at 2.000rpm
Gave +1 Rep to @slow cloud (current: #62 - 168)
Only time I've driven fast was at midnight on a highway
And even then, it was only 120-130km/h
only time i driven fast fast was on the autobahn
160, my car was not making good noises
I could've easily topped it at 160 but yeah
All the roads where I live are 40 or 50, however it feels like I'm the only one that followrs the speed limit 
Every kmh matters at high speed
yo guys can I ask here a question on the use of hydra?
I have a a speeding ticket which I wonβt say how much I was going
120 is the norm here after 7pm
Sure
Go for it
What's up
But it was on a highway
Can i send screenshots?
I've been staring at ghidra for four days 
To add a screenshot, you need to verify:
β¨https://help.tryhackme.com/en/articles/6495858-discord-how-do-i-verify-my-tryhackme-account
All about TryHackMe Discord Server.
and it was a straight road
Eeek I'm terrified of being pulled over, but I do rely on the car quite a bit
lol
km/h???
Speeding tickets meh, none of the speed cameras work π€£
yes
the guy who pulled me over
was
So nice
what is the limit
120
My car had a somewhat "illegal" feature, where I could tilt the plates
I never got pulled over
after 7pm, before 7pm its 100
Like he told me the speed i was going was enough to immediately jail me
But that's cause it was a ute
infinity in Germany
Or a "truck" as Americans call it
But let me off with a ticket of just 30β¬
I have uid 0 on my car system 
So the hydraulics were so the plate was visible if the back was done for whatever reason
90 in a school zone?
wish we had it tbh
but it wouldn'\t safe because our driving tests are fucking nothing compared to europes
the MAX is 110
but it is typically 100
It was on a highway
I think the gov are giving me a laptop because I broke mine
No speeding tickets yet
I was really unlucky bc normally no one gets one
But it was a Sunday and the law enforcement was bored
yo guys i verified!
I've sped past law enforcement before
In the UK speeding is very strict, 3 points for speeding and 12 points* in a 3 year period results in you losing your license
My father has a ton of points and he has had to take a speed awareness course at least 5 times
lucky
So why does hydra tell me these passwords when they are not the correct ones?
I would freeze up π
I should've been pulled over
Damn
Im in Greece
Points, damn
People here feel like laws donβt apply to them
If you get caught speeding within 1 year of getting your license, you lose it
LOL
Thatβs super strict
but I guess it makes sense
Is this for a TryHackMe Room?
if you drive 30kmph over the limit here and you get caught you lose your license as a beginner. more experienced driver is 50kmph too fast
Yeah here it was the same
If not: have you been giving written and signed permission by both you and the contractor to perform this
It was immediately going to court + losing your license
no, for practice
And if it's a VDP: why are you exposing this here
But the officer just gave me a 30β¬ ticket bc I was super nice
is this a public website?
So theyβre giving more leeway for more experienced drivers. That doesnβt make sense
Have you been given permission by the site owner?
yes
Is it signed by you and them in a legally binding contract?
whoops
Y u don't run from cops /j
With these knees. I would just give up
Okay
Illegal is maybe a bit far
Yeah this is potentially illegal lol
Cause if there's no contract here or if it's a VDP they're in breach
well if you are more experienced you can handle yourself better in a dangerous situation
btw do you know the answer to my question? It was a bout hydra not a random site
Which can lead to lawsuits
Cuz that way itβs certified jail time
Plus I was with my gf and my cat
Only if they catch u
/j
Yeah but there are tolls
really? how so? at which point does it cross into being illegal?
Damn I can relate sis 
I think crashes are too unpredictable to be able to be a βBetterβ driver in any situation. 
Itβs as simple as saying
Can confirm

Howβs your holiday ?
true
Donβt open the toll gate for license plate xyz
Yo guys do you mean using hydra to crack passwords is illegal?
I've had too many near collisions
There are no better driver itβs purely biology and human reflexes
Had my car for three years
Ur brain canβt physically predict sth better than 1 sec
Nearly totalled it cause of a dumbass truck driver
Look at F1
They are in a totally controlled environment and they are almost at 1 sec too
driving for 11 years now, gladly no crash or similar yet
I used to go out on a bicycle when I was younger, Everywhere. I had almost been hit by so many cars. I even once rode directly into a wall. π
Good good
@knotty valve
guys the best hacker here is @slow cloud
Iv been booped :o
am i?
No it's r00t
yeah ofc

imo its ryan
This was my cat today. What is he ?

no the best hacker here is : @marsh lark
:D
well
I can agree to that
Model 
Bro we know that you hack all the Windows servers
He actually is. He was up screaming for bitches all night and then pissed on my book to rebel.
quick question donut
He was just cleaning the book

yes?
6 months ago
on thm
π€«π€«π€«
There's a lot of moving parts here. NAL.
IF they have permission to pentest the website, then they're not performing an unauthorised pentest.
However, generally we advise to have some sort of contract which is signed both parties to protect them legally, i.e. if the pentester breaks the website, and there's no contract, the website owner could take them to court and there would be little to protect them.
OR the website owner should have a public program which states the terms of the engagement.
Another problem is that you may also need permission if you are using a hosting company to permit users to pentest your website (that would be the responsibility of the website owner, not the pentester). Not a lot of website owners know about this - it is also subjective to the hosting company
TL;DR Just having permission from the website owner verbally or casually isnβt usually enough protection for a pentester. Without a written agreement, they could still get into legal trouble if damage occurs.
Please feel free to correct if any of that is wrong^
why dont u do rooms on thm
Does anyone know if ProtonVPN is a good Vpn for an hacker?
I'm cursed 
Can u pin this, it's very useful 
OH and I find it super unlikely that a website would want someone to brute force a login page
how much is a lot
uhhh
ProtonVPN is an excellent VPN in terms of daily use and for normal users, since it's based in Switzerland, but I would not advice using any VPN for hacking
12 hours a day
he put the same question in #cyber-and-careers 
exactly
yeah, no, my assumption was that he has no permission whatsoever; he didn't state it, but just my guess based on the type of question he asked; then performing any kind of pentest except for maybe osint is illegal, right?
It is used a fair bit but any good "hacker" won't use a public VPN unless they're just looking for basic protection
Heβs so naughty. I was forced to sleep on the sofa
thank u now i will start doing 12 hours a day as well
Gave +1 Rep to @marsh lark (current: #32 - 338)
mullvad is best vpn
What Jabba said.
Damn
Missing detail: for public programs, you're not actually allowed to disclose anything until you've been authorised to do so, in writing, otherwise it breaches Safe Harbour and Rightful Disclosure which will lead to lawsuits
They said "yes" to Ashlynn's question, however here we don't allow these types of question unless a moderator can see the contract; no contract, no help
He threatened me at claw point
jabba is the fat guy from star wars right
You guys won't be allowed to see the contract, those contracts are written as an NDA, so I'd be VERY careful asking since you could I directly cause a lawsuit or have THM sued for breaching their NDA
Yes! Great point - also following responsible disclosure even if you're allowed to discuss them - always speak to the company first and make sure that the vulnerability is patched
@mossy river Can i get your help about problem i faced while trying to sign in in dms ?
pookie
can someone make a 1:1 replica of jabba as a
how do u call these chairs
that arent chairs
but pillows
u sit on
uhmmmmmmmmm
help me
i cant remember
Contracts are only viewable by the following, for context:
- signed parties
- law enforcement
- court systems
- either parties' law advocate (lawyers, and such)
bean bag
Bean bags
tooooo sloooooow
Bean
yes a bean bag
Damn jack is fast 
can u make a bean bag like jabba

i dont use google
Damn
i send a pigeon with a note
yeah we can tell
to smart people
you use us as google
Avian TCP
π
sorry
I'm taking orders starting now
I hate it
I LOVE IT
ur mean
I am in driving school but I sometimes go and drive for fun
Yooo I got my bike and pillow, thanks 
Gave +1 Rep to @river garden (current: #79 - 121)
i would love to sit on him and watch cool movies
thats so mean; I poured so much soul and work into this

goodboiii
I struggle with changing gears and leaving the clutch too fast which causes my car engine to stall and shut off
awesome!! I'll let u now when gfs are available again
Cool 
Bc I just moved
Better than mine 
everything comes with practice! for me it's the most easiest thing to do
Sup c
I have a cheap car (my father's old one) which I use for practice and fun driving
u are missing something
Few things here;
- No, TryHackMe would not be liable for any of it's employees or individuals for asking to see a contract. If you breach your NDA, that doesn't make anyone else liable.
- If you do have a contract, and we ask to see it, and then you say "I can't because I am bound by an NDA", it sort of ties it up into a neat little bow that you should be asking here anyway so we won't need to see the contract π
try to hold the clutch a little bit instead of just letting it go
c0mplexity or co, you can call me like that. Nothing, enjoying my coffee wbu?
that's Genshin Impact
Hello ππ»
My bad co
Me good
where is a cup of coffee eh?
Sup
can someone make an ai based distro and instead of tools it comes with installed with ai models
and everything is done buy ai
as it should be, lit
its even made with ai....
look nice, what brand of computer monitor are u using?
yeah I can do it gimme 5 mins
Yea that's what I'm trying to master
Making myself another one
Samsung
good because it adds +1 point to the setup
lol it still needs fixing
buy femboy socks and put them on the wall
Ah, don't worry about it, still happens to me every now and then.
Honestly my best advice is don't worry about anyone else on the road, most people dump the clutch because they're trying to pull off to quickly, mainly because there's someone behind them I do know that sometimes it's unavoidable to go slowly
Another thing is sometimes adding a little gas can help prevent a stall, however I really emphasise the fact that it is a little gas, if you jump to 3k revs you're going to wheelspin and jolt the car π€£
+1.000.000 points to thinking
First point I'd like to counter with: how the employee asks the question (or if there's persistence) changes this completely. Mainly due to coercion, if it was to be asked as "well you can't discuss it here until I see your contract" or "you have to (must also works) send the contract before we can let you talk about [X]" there can be legal issues
Something to be aware of
U use an iphone


I understand
Yea I do give a very little bit amount of gas on 1st and 2nd gear
you should give more gas
how do u know
And never had to use 5th gear
my issue was always using too little gas
The charger?
Cause this is a great sentence that could he used against THM in such cases, if the contractor was to find out
U showed too much 
Phrasing is a legal hell
Yk what I hate, driving while sleepy
I was sleepy rn while driving cause I was tired, and I almost hit a biker
B u t β¦
I think you need to shift earlier bro
LMFAO
I'm probably gonna take a nap for an hour or two
Any idea where I can learn from pros? Pen testing or red teamer? I want to see how everything runs in the real world
Cause I'm sleepy as hell
Try playing #koth
are you driving 6k rpm non stop or what
It's a fun way to simulate engagements
No no lmao
You shouldn't be driving when you are tired or sleepy! It's in the learning theory, you risk your own life and life of others.
Yea I'm aware
Today I was tired of sitting on my PC for studying so I thought I'll go on a drive for fun
Turns out I was tired
I mean i don't know where to drive to be honest, i passed my exam in 2023
and i haven't been driving much
only if i need something
I'm very new to driving
or drive to my gf
depends where you are from in which country
I've found driving to be a fun freeing experience
I just drive randomly to some road I haven't been to before
with a car or bike?
It's alright 
Yaa driving in fun ngl
bike is better, car is too clumsy
For solo, yes. If you're driving with someone then nah
bike is goated


